Skip to main content

Capability

Enum Capability 

Source
#[repr(u16)]
pub enum Capability { LocalRead = 1, LocalWrite = 2, FixedConnectorRead = 4, ArbitraryEgress = 8, MutateExternal = 16, GrantAccess = 32, RevokeAccess = 64, ManageAdmin = 128, GrantAdmin = 256, }
Expand description

One thing a tool call can do — the unit of the containment model.

The taxonomy is deliberately small and rarely changes. Adding a member means extending this enum and the two derivation functions (required_capabilities, granted_capabilities); the decision engine (decide) operates on sets generically and never needs to change (a pinned test demonstrates this).

Variants§

§

LocalRead = 1

Read state confined to the conversation’s sandbox (workspace files).

§

LocalWrite = 2

Mutate state confined to the conversation’s sandbox (workspace writes, sandboxed shell). Destructive inside the box is still local.

§

FixedConnectorRead = 4

Call an operator-registered connector endpoint (or a first-party control-plane service) — a fixed destination the operator vouched for, carrying only model-authored arguments. Taint never revokes this.

§

ArbitraryEgress = 8

Send bytes to a model-controlled external destination — the built-in web/paid fetchers. The classic exfiltration channel.

§

MutateExternal = 16

Perform a side effect outside the sandbox: mutate external state, send a message, file an issue, spend money. An external mutation carries model-authored bytes to destinations an attacker may read, so it is an egress channel in effect even when the destination is fixed.

§

GrantAccess = 32

Grant a third party access to the system itself — the admin invite (#700). Deliberately held OUT of Self::ALL, so it is never in CapabilitySet::all, never in the default grant, and — because Self::from_name only recognizes members of Self::ALL — unnameable in operator config: no policy or wire input can ever seed it into a granted set. A tool that requires it therefore always exceeds its granted set and always escalates to a human, in every taint state and policy mode. This is the structural mechanism behind “an access-grant is never autonomous — a person always confirms the exact invitee”.

§

RevokeAccess = 64

Remove a third party’s access to the system itself — the admin de-admission (#713), the offboarding sibling of Self::GrantAccess. Held OUT of Self::ALL for the identical reason: never in CapabilitySet::all, never in the default grant, and unnameable in operator config (Self::from_name only recognizes Self::ALL members), so a tool requiring it always exceeds its granted set and always escalates to a human, in every taint state and policy mode. This is the structural mechanism behind “a removal is never autonomous — a person always confirms the exact person being removed”.

§

ManageAdmin = 128

Take away a persona’s ADMIN ROLE — the demote tool (#715), and the sibling that completes the admin-management set alongside Self::GrantAccess/Self::RevokeAccess. Held OUT of Self::ALL for the identical reason: never in CapabilitySet::all, never in the default grant, and unnameable in operator config (Self::from_name only recognizes Self::ALL members), so a tool requiring it always exceeds its granted set and always escalates to a human, in every taint state and policy mode. This is the structural mechanism behind “an admin’s role is never removed autonomously — a person always confirms exactly whose role is being taken away”.

This used to occupy the last bit u8 could hold (1 << 7); adding Self::GrantAdmin widened CapabilitySet (and this enum’s #[repr]) from u8 to u16, so a further marker needs no more widening — u16 has eight bits to spare.

§

GrantAdmin = 256

Make a persona an ADMIN — the promote tool (POLY-223), the admission-granting sibling of Self::ManageAdmin that completes the admin-management set alongside Self::GrantAccess/ Self::RevokeAccess. Held OUT of Self::ALL for the identical reason: never in CapabilitySet::all, never in the default grant, and unnameable in operator config (Self::from_name only recognizes Self::ALL members), so a tool requiring it always exceeds its granted set and always escalates to a human, in every taint state and policy mode. This is the structural mechanism behind “an admin role is never granted autonomously — a person always confirms exactly who is being made an admin.”

Deliberately its OWN marker rather than a reuse of Self::ManageAdmin: the escalation copy the gate renders is directional (see escalation_reason) — reusing ManageAdmin would make a PROMOTION’s approval card read “would take away someone’s admin role,” the opposite of what is actually being authorized.

Implementations§

Source§

impl Capability

Source

pub const ALL: [Self; 5]

Every grantable member of the taxonomy, in declaration order.

Self::GrantAccess and Self::RevokeAccess are deliberately absent: they are the never-granted markers (see their docs), so they are excluded from CapabilitySet::all, the default grant, name parsing (Self::from_name), and set iteration — everything driven off this array operates only over the grantable set.

Source

pub const fn as_str(self) -> &'static str

Stable kebab-case name, used in signed approval coverage and telemetry. Inverse of Self::from_name.

Source

pub fn from_name(name: &str) -> Option<Self>

Parse a stable kebab-case name; None for anything unrecognized so a caller reading operator config fails toward granting nothing.

Trait Implementations§

Source§

impl Clone for Capability

Source§

fn clone(&self) -> Capability

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for Capability

Source§

impl Debug for Capability

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for Capability

Source§

impl FromIterator<Capability> for CapabilitySet

Source§

fn from_iter<I: IntoIterator<Item = Capability>>(iter: I) -> Self

Creates a value from an iterator. Read more
Source§

impl Hash for Capability

Source§

fn hash<__H: Hasher>(&self, state: &mut __H)

Feeds this value into the given Hasher. Read more
1.3.0 · Source§

fn hash_slice<H>(data: &[Self], state: &mut H)
where H: Hasher, Self: Sized,

Feeds a slice of this type into the given Hasher. Read more
Source§

impl Ord for Capability

Source§

fn cmp(&self, other: &Capability) -> Ordering

This method returns an Ordering between self and other. Read more
1.21.0 (const: unstable) · Source§

fn max(self, other: Self) -> Self
where Self: Sized,

Compares and returns the maximum of two values. Read more
1.21.0 (const: unstable) · Source§

fn min(self, other: Self) -> Self
where Self: Sized,

Compares and returns the minimum of two values. Read more
1.50.0 (const: unstable) · Source§

fn clamp(self, min: Self, max: Self) -> Self
where Self: Sized,

Restrict a value to a certain interval. Read more
Source§

fn clamp_to<R>(self, range: R) -> Self
where Self: Sized, R: ClampBounds<Self>,

🔬This is a nightly-only experimental API. (clamp_to)
Restrict a value to a certain range. Read more
Source§

impl PartialEq for Capability

Source§

fn eq(&self, other: &Capability) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl PartialOrd for Capability

Source§

fn partial_cmp(&self, other: &Capability) -> Option<Ordering>

This method returns an ordering between self and other values if one exists. Read more
1.0.0 (const: unstable) · Source§

fn lt(&self, other: &Rhs) -> bool

Tests less than (for self and other) and is used by the < operator. Read more
1.0.0 (const: unstable) · Source§

fn le(&self, other: &Rhs) -> bool

Tests less than or equal to (for self and other) and is used by the <= operator. Read more
1.0.0 (const: unstable) · Source§

fn gt(&self, other: &Rhs) -> bool

Tests greater than (for self and other) and is used by the > operator. Read more
1.0.0 (const: unstable) · Source§

fn ge(&self, other: &Rhs) -> bool

Tests greater than or equal to (for self and other) and is used by the >= operator. Read more
Source§

impl StructuralPartialEq for Capability

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more